Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add lovstudio/skillsnpx agentmods add plugins/lovstudio/skills/dev-toolsgit clone --depth 1 https://github.com/lovstudio/skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/lovstudio/skills/dev-tools)<a href="https://agentmods.dev/plugins/lovstudio/skills/dev-tools"><img src="https://agentmods.dev/badge/plugins/lovstudio/skills/dev-tools.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
dev-tools scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "dev-tools",
"source": "./",
"description": "Dev Tools — 31 free skills bundled together.",
"category": "Dev Tools",
"skills": [
"./skills/env-management",
"./skills/mobile-adapt",
"./skills/repo2docs",
"./skills/auto-context",
"./skills/cc-migrate-session",
"./skills/deploy-to-vercel",
"./skills/finder-action",
"./skills/gh-access",
"./skills/gh-contribute",
"./skills/gh-tidy",
"./skills/install-tanstack-query",
"./skills/release-via-cicd",
"./skills/optimize-tauri-backend",
"./skills/app-generator",
"./skills/electron-delta-updater",
"./skills/electron-app-relaunch",
"./skills/install-ai",
"./skills/skill-distiller",
"./skills/skill-pricing",
"./skills/skill-publisher",
"./skills/obsidian-reset-cache",
"./skills/project-port",
"./skills/clash-tun-doctor",
"./skills/ataru-indexing",
"./skills/search-chat",
"./skills/open-codex-session",
"./skills/integrate-lovinsp",
"./skills/dsh-plugin-creator",
"./skills/dsh-plugin-publisher",
"./skills/npm-publisher",
"./skills/cli2anything"
],
"strict": false
}What it installs
The manifest is a name and a version. 31 skills travel with it, and installing the plugin installs all of them — 2,785 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill lov-app-generator A 66 tokens
- Skill lov-release-via-cicd A 98 tokens
- Skill dsh-plugin-publisher A 82 tokens
- Skill lov-npm-publisher A 85 tokens
- Skill lov-optimize-tauri-backend A 125 tokens
- Skill lov-skill-pricing A 78 tokens
- Skill lov-skill-publisher A 38 tokens
- Skill lov-auto-context A 112 tokens
- Skill lov-clash-tun-doctor A 122 tokens
- Skill lov-env-management A 53 tokens
- Skill lov-finder-action A 104 tokens
- Skill lov-gh-access A 151 tokens
- Skill lov-gh-contribute A 102 tokens
- Skill lov-install-tanstack-query A 110 tokens
- Skill lov-integrate-lovinsp A 130 tokens
- Skill lov-repo2docs A 186 tokens
- Skill lov-deploy-to-vercel A 92 tokens
- Skill lov-mobile-adapt A 105 tokens
- Skill lov-search-chat A 53 tokens
- Skill dsh-plugin-creator A 60 tokens
- Skill lov-ataru-indexing A 55 tokens
- Skill lov-cli2anything A 55 tokens
- Skill lov-gh-tidy A 95 tokens
- Skill lov-open-codex-session A 56 tokens
- Skill sgc-skill-distiller A 79 tokens
- Skill lov-project-port A 75 tokens
- Skill sgc-install-ai A 68 tokens
- Skill sgc-electron-delta-updater A 71 tokens
- Skill sgc-electron-app-relaunch A 67 tokens
- Skill lov-cc-mv C 132 tokens
- Skill lov-obsidian-reset-cache C 80 tokens
What ships with it
1 file beside marketplace.json#dev-tools in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 40 lines scan A de3fac611aad
dev-tools is a plugin published in the GitHub repository lovstudio/skills (64 stars, last pushed today), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
claude-settings marketplace
Plugin marketplace listing 36 plugins: simplify, humanize, fable-advisor, codex-advisor, adhd-output-style.
gcloud-tools
Google Cloud Observability MCP for logs, metrics, and traces, plus best practices.
anthropic-office-skills
Official Anthropic skills for PDF, Word, PowerPoint, and Excel files.
ainb-fleet
LLM-facing skill teaching agents how to spawn ainb sessions correctly and how to use ainb fleet ... orchestration subcommands. Spawning covers the ainb run contract (always into a git worktree, plus the --parent shapes that silently misfire). Fleet covers multi-session broadcast, ack-gated sequence, blocked-sessi.
code-discipline
Coding methodology for production-grade software development. Six principles: think before coding, verify reality, simplicity first, surgical changes, respect existing contracts, goal-driven execution.
nestjs-best-practices
12 NestJS best-practice skills (90 rules) covering modules & DI, controllers, validation, guards/auth, interceptors, exception filters, config, database, caching/queues, testing, security, and performance/logging.